Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.142521
Category:Denial of Service
Title:Samba 4.10.0 < 4.10.5 DoS Vulnerability (CVE-2019-12436)
Summary:Samba is prone to a denial of service vulnerability.
Description:Summary:
Samba is prone to a denial of service vulnerability.

Vulnerability Insight:
A user with read access to the LDAP server can crash the LDAP server process.
Depending on the Samba version and the choice of process model, this may crash only the user's own connection.

Specifically, while in Samba 4.10 the default is for one process per connected client, site-specific
configuration triggers can change this.

Affected Software/OS:
Samba versions 4.10.x.

Solution:
Update to version 4.10.5 or later.

CVSS Score:
4.0

CVSS Vector:
AV:N/AC:L/Au:S/C:N/I:N/A:P

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2019-12435
BugTraq ID: 108825
http://www.securityfocus.com/bid/108825
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZQ3LCJNJ3ONHIRKDSKOTT6QGXALLCHVG/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/QSG3TLPZP35RH5DWAIDC7MHXRK5DFKOE/
SuSE Security Announcement: openSUSE-SU-2019:1755 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2019-07/msg00023.html
https://usn.ubuntu.com/4018-1/
CopyrightCopyright (C) 2019 Greenbone Networks GmbH

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.